risk-register

Seed and manage a SOC 2 CC3.1 risk register from Shasta scan findings.

7|2|Updated Apr 3, 2026
One-click install
npx skills add https://github.com/kkmookhey/shasta --skill risk-register-kkmookhey
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: risk-register
Source: https://github.com/kkmookhey/shasta/tree/main/.claude/skills/risk-register
Command: npx skills add https://github.com/kkmookhey/shasta --skill risk-register-kkmookhey

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

SOC 2 CC3.1 compliance requires a living risk register that tracks control gaps, remediation actions, and audit evidence. This Skill helps founders create and maintain such a risk register by auto-seeding from cloud scans, tracking treatment, and exporting audit-ready reports.

Core Features & Use Cases

  • Auto-seed risks from the latest Shasta scan and generate a structured risk register.
  • Track ownership, status, and remediation actions for each risk, with quarterly reviews.
  • Generate audit-ready evidence bundles to support SOC 2 compliance and governance programs.

Quick Start

Run the risk-register skill to seed the register from your most recent Shasta scan and begin assigning owners and treatments.

Frequently Asked Questions about risk-register

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I build a SOC 2 CC3.1 risk register from cloud scan findings?

You can build a SOC 2 CC3.1 risk register by auto-seeding risks from your latest Shasta scan, which populates a structured register ready for tracking remediation and generating audit-grade compliance evidence.

Can I track remediation actions and ownership for SOC 2 compliance risks?

Yes, you can assign owners, track statuses, and manage remediation treatments for each risk in the register, maintaining a living record that supports quarterly compliance reviews.

How do I generate audit-ready evidence for SOC 2 risk management reviews?

You generate audit-ready evidence by running the risk register to compile tracked control gaps, assigned ownership, and remediation statuses into structured reports designed for compliance reviews.

Do I need a Shasta configuration to manage a SOC 2 risk register?

Yes, you need a Shasta configuration that provides a python_cmd and uses ShastaDB initialization to read your scan results and populate the risk items automatically.

What is the best way to automate risk management for SOC 2 governance?

The best way to automate risk management for SOC 2 is to seed your register directly from cloud scan outputs, automatically tracking control gaps and treatments to maintain continuous compliance.